Out-of-bounds read In nss
Description
Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue exists because of an incomplete fix for CVE-2010-2753.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:2.0.0.24-8.el5 | ||
rpm rhel5 | 0:3.12.7-2.el5 | ||
rpm rhel5 | 0:3.6.9-2.el5 | ||
rpm rhel5 | 0:4.8.6-1.el5 | ||
rpm rhel5 | 0:1.9.2.9-1.el5 |
Aliases
1. 2. 3.